Operation Olympic Games (Stuxnet Industrial SCADA Cyberweapon)
Key Facts
- Legal Status: UNCHARGED in U.S. Federal Executive Attribution.
- Primary Target Sector: Industrial Manufacturing, Critical Infrastructure, Energy.
- Documented Financial Loss: $1.0 billion.
- 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Four zero-day Windows vulnerabilities combined with weaponized Siemens Step7 logic and stolen Realtek and JMicron digital certificates, delivered via infected USB flash drives.
Operational & Financial Fallout
Physically damaged approximately 1,000 IR-1 uranium enrichment centrifuges at Iran's Natanz enrichment facility, delaying the Iranian nuclear enrichment program by an estimated two years.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Four zero-day Windows vulnerabilities combined with weaponized Siemens Step7 logic and stolen Realtek and JMicron digital certificates, delivered via infected USB flash drives.
Adversary Kill Chain Flow
3 Documented PhasesOperatives deployed Stuxnet via USB thumb drives exploiting a Windows shortcut rendering zero-day (CVE-2010-2568), executing code automatically the moment a user browsed the drive in Windows Explorer.
The worm verified whether the host was running Siemens Step7 or WinCC software connected to specific frequency converter drives manufactured by Fararo Paya and Vacon.
Stuxnet intercepted communications with the Siemens S7-300 PLCs, commanding the centrifuges to spin up to 1,410 Hz (causing physical rotor destruction) while transmitting prerecorded normal sensor readings back to the operators.
Physically damaged approximately 1,000 IR-1 uranium enrichment centrifuges at Iran's Natanz enrichment facility, delaying the Iranian nuclear enrichment program by an estimated two years.
Procedural & Incident Timeline
VirusBlokAda security firm identifies Stuxnet worm propagating in the wild on infected Windows systems.
CISA publishes technical advisory on Stuxnet targeting Siemens Simatic Step7 and WinCC industrial control software.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application Initial Access | "Stuxnet utilized a Windows zero-day vulnerability in shortcut icon rendering (CVE-2010-2568 LNK vulnerability) allowing automatic binary execution upon viewing a malicious USB drive in Windows Explorer." | Symantec Security Response Technical Dossier v1.4, Page 14 | reviewed |
| T1485 | Data Destruction Impact | "The worm intercepted Siemens Step7 communications with programmable logic controllers (PLCs), secretly overriding centrifuge rotational frequencies while transmitting recorded normal telemetry back to control room displays." | CISA Industrial Control Systems Advisory ICSA-10-272-01 | reviewed |